All Apps and Add-ons

Huge Lookup File on Search Head by Tripwire Application ( te_assets.csv )

msocops
Loves-to-Learn

Hello Splunk Community members,

I am facing an issue with Tripwire, on splunk. It is generating this humongous file ( te_assets.csv ) approximately 26 GB within an hour. Due to this the splunk service stops as in the Search Head there is only a single partition.

Seems like Tripwire keeps updating splunk lookup with a fresh copy of assets data. Is there a way to limit the generated lookup file on Splunk? Or any config changes to be done from Tripwire Side?

Your help/feedback is highly appreciated.

 

Thanks

Labels (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!